vendor:
Symphony CMS
by:
Eldar "Wireghoul" Marcussen
N/A
CVSS
N/A
Blind sql injection
89
CWE
Product Name: Symphony CMS
Affected Version From: 2.1.2002
Affected Version To: 2.1.2002
Patch Exists: NO
Related CWE:
CPE: a:symphony-cms:symphony_cms:2.1.2
Platforms Tested:
2011
Symphony-cms blind sql injection
The symphony cms login page does not sufficiently filter user supplied variables used in a SQL statement, resulting in a blind sql injection vulnerability.
Mitigation:
Update to version 2.1.3 or higher.